Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Telegram Ban India Crypto, TON & Durov's Attack on Reliance
    Telegram Ban in India: Crypto, TON & Durov’s Attack on Reliance
    Hormuz Peace Dividend How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Hormuz Peace Dividend: How the US-Iran Deal Fuels Dubai RWAs & Not Tehran
    Kevin Warsh's First FOMC What It Means for Bitcoin and Crypto
    Bitcoin and the ‘Fed Chair Curse’: What Kevin Warsh’s First FOMC Means for Crypto
    Crypto Tax Overhaul What Congress’s New Framework Means for 60M Americans
    Crypto Tax Overhaul: What Congress’s New Framework Means for 60M Americans
    One Laptop, $36 Million, and a Token Collapse Inside the Humanity Protocol Exploit
    Humanity Protocol $36M Exploit: 447M $H Hit After Laptop Breach and Multisig Failure
  • Opinion
    OpinionShow More
    The Arthur Hayes Paradox Macro Prophet or Market Opportunist
    The Arthur Hayes Paradox: Macro Prophet or Market Opportunist?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India's Digital Rupee Push?
    RBI Denies Gold Sale Amid Oil Crisis: Could It Speed Up India’s Digital Rupee Push?
    The CLARITY Act War Starts Jamie Dimon Vs Armstrong
    The CLARITY Act War Starts: Jamie Dimon Vs Armstrong
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino
    Is Crypto Dying, or Is Pump.fun Turning It Into an Attention Casino?
    CoinSwitch on TMKOC India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It_
    CoinSwitch on TMKOC: India Saw a ₹100 Crypto Pitch, But Not the Risks Behind It
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Ethereum News

Mysterious Wallet Drains 326 ETH from Over 570 Ethereum Addresses

Unlike typical "drainer-as-a-service" scams that rely on tricked approvals for ERC-20 tokens, this operation pulled almost exclusively native ETH.

Written By:
Gopal Solanky

Last updated: May 1, 2026 6:23 PM
Published 2026-05-01
Share
Mysterious Wallet Drains 326 ETH from Over 570 Ethereum Addresses
Show AI Summary
An Ethereum address drained funds from over 570 wallets within 13 hours, stealing around $760,000 in ETH between April 29 and 30, 2026.
The attacker consolidated stolen ETH before bridging it through THORChain into Bitcoin and Monero, effectively laundering funds across chains.
The operation’s speed and selectivity peaked with 244 wallets emptied in one hour, with private key compromises likely due to leaked credentials from past breaches.

In a sophisticated operation spanning just 13 hours, a single Ethereum address drained funds from more than 570 wallets, making off with approximately 326 ETH worth around $760,000—as per onchain data from Etherscan. 

The incident, which unfolded between April 29 and 30, 2026, has raised fresh concerns about the long-term security of self-custodied crypto assets, particularly older wallets. 

The exploiter address, flagged as Fake_Phishing2831105 on Etherscan, consolidated the stolen ETH before bridging the bulk of it, roughly 324.74 ETH, through THORChain into Bitcoin and Monero, effectively laundering the funds across chains. 

Rapid sweep target mixed wallets

The attack stood out for its speed and selectivity. At its peak, the drainer emptied 244 wallets in a single hour. What puzzled observers was the victim profile. While some wallets had sat dormant for over eight years, others had shown recent activity. A handful had never sent any outgoing transactions at all. 

Unlike typical “drainer-as-a-service” scams that rely on tricked approvals for ERC-20 tokens, this operation pulled almost exclusively native ETH. That signature strongly suggests the attacker possessed the private keys, allowing them to sign transactions directly from the victims’ wallets without any user interaction or malicious smart contract. 

As of now, no widespread phishing campaign or compromised decentralized application has been linked to the incident. Many victims reportedly discovered the losses only after checking their balances, with little to no warning.

Private key compromises likely culprit

Analysts point to leaked credentials as the most plausible explanation. The 2022 LastPass breach, in which encrypted password vaults were stolen, remains a prime suspect. Security researchers have previously tied similar unattributed thefts to offline cracking of those vaults, a process that improves with time and computing power. 

Ethereum Dormant Wallet Drain, April 30, 2026

A wallet labelled by Etherscan as Fake_Phishing2831105 has been receiving funds from many addresses and rapidly moving them through swaps and cross chain infrastructure.

The address is:

0xA707034429c8E4E01df056C0CbCf478F0FBeFAd7… pic.twitter.com/CVqo9mwGAQ

— MASTR (@MastrXYZ) April 30, 2026

Other potential vectors include compromised wallet software, trading bots that require users to input private keys, or supply-chain attacks on development libraries. The mixed age of the drained wallets supports the idea of an aggregated list drawn from multiple historical leaks. 

After the final drain around 12:39 UTC on April 30, they waited several hours before testing small transfers, then executed the large bridge in one transaction. This level of operational discipline is typical of experienced on-chain criminals.

Broader implications for crypto security

The incident serves as a stark reminder that “cold” wallets are not immune to risk if their keys were ever exposed. Forgotten wallets from the ICO era or early DeFi days can become liabilities years later if seeds or private keys were stored insecurely. 

Security professionals recommend generating fresh wallets on hardware devices for any remaining funds and avoiding reuse of older seed phrases. 

As of now, there is no indication of a flaw in Ethereum’s core protocol. The blockchain simply processed validly signed transactions. The vulnerability lies in the persistent human and infrastructure weaknesses that continue to expose keys long after initial compromises. 

This event adds to a growing list of private-key-based thefts that highlight the permanent nature of blockchain transactions: once keys are lost, recovery options are nonexistent. For now, the attacker remains unidentified, and the full scope of compromised credentials may never be publicly known. 

This is a developing story. More information will be updated as the event unfolds. 

Also read: Carrot Becomes First DeFi Casualty of $285M Drift Exploit

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto Hack
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Gopal Solanky, Senior Reporter for Markets and Protocols at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Senior Reporter, Markets & Protocols at The Crypto Times, based in Ahmedabad. He covers institutional crypto adoption, Bitcoin treasury strategies, DeFi markets, protocol ecosystems, Ethereum network activity, Hyperliquid, on-chain trends, and broader digital asset market movements. Gopal has been active in the crypto ecosystem for more than six years. Before joining The Crypto Times full-time in 2023, he worked as a freelance crypto content writer, developing a strong understanding of blockchain infrastructure, DeFi protocols, market cycles, token mechanics, and peer-to-peer systems. His reporting focuses on explaining how protocols work, why market movements happen, and how institutional and on-chain activity affects crypto investors and builders. At The Crypto Times, Gopal regularly writes market analysis, protocol explainers, breaking news, and technical breakdowns across Bitcoin, Ethereum, DeFi, altcoins, treasury companies, and Web3 infrastructure. He also conducts on-the-record interviews with regional Web3 founders, protocol teams, and ecosystem leaders. His work has been cited by external publications, including Vulture.com, in coverage of major crypto stories such as the Hawk Tuah memecoin controversy. His reporting has also contributed to The Crypto Times’ coverage of major industry events, including FTX-related developments, institutional crypto adoption, and emerging protocol narratives. Gopal holds a Bachelor’s degree in Computer Applications, giving him a technical foundation for analyzing blockchain systems, crypto infrastructure, and market data.

Latest News

Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Ireland Targets Crypto Risks in New 30-Point Crime Action Plan
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Celsius Founder Hit With Lifetime Ban as CFTC Closes Case
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Kraken Unlocks 2,500+ Solana Tokens Without Leaving Its App
Sen. Gillibrand's Son Bets on Perpetual Futures With $30M Raise
Sen. Gillibrand’s Son Bets on Perpetual Futures With $30M Raise
Hyperliquid Fires Back at CME Over CFTC Perpetual Futures Lawsuit
Hyperliquid Fires Back at CME Over CFTC Perpetual Futures Lawsuit

Find Us on Socials

You may also like

Aztec Network’s RollupProcessor Exploited for $2.21 Million

Aztec Network’s RollupProcessor Exploited for $2.21 Million 

UXLINK Exploiter Moves 8,340 ETH—Then Sends It to Tornado Cash

UXLINK Exploiter Moves 8,340 ETH—Then Sends It to Tornado Cash

Humanity Starts H Token Airdrop After $36M Exploit Fallout

Humanity Starts H Token Airdrop After $36M Exploit Fallout

Humanity Protocol Unveils H Token Recovery and Airdrop Plan Post $36M Hack

Humanity Protocol Unveils H Token Recovery and Airdrop Plan Post $36M Hack

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information